On Mon, May 04, 2015 at 12:23:56PM +0200, Daniel Borkmann wrote: > This adds iptables user space part for configuration of flextuples. > I also noticed that ct_print*() zone reporting had a whitespace bug, > which is fixed here as well (it needs to be prefixed). I would really like not to overload the ct template thing with more features. This started as a simple way to indicate what features are available in the conntrack. We have discussed already that we should provide a way to enable conntrack from a rule, this rule should indicate all of the features that you want to attach to that conntrack. This requires a /proc switch to disable the existing behaviour to avoid breaking backward. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html